The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.
- http://securityreason.com/securityalert/4452
- https://www.exploit-db.com/exploits/6779
No PoCs found on GitHub currently.